7.8

CVE-2021-38160

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.24 < 4.4.276
Linux ≫ Linux Kernel Version >= 4.5 < 4.9.276
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.240
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.198
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.134
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.52
Linux ≫ Linux Kernel Version >= 5.11 < 5.12.19
Linux ≫ Linux Kernel Version >= 5.13 < 5.13.4
Netapp ≫ Hci Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Solidfire Version -
Netapp ≫ Element Software Version -
   Netapp ≫ Hci Storage Node Version -
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Redhat ≫ Enterprise Linux Version 8.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2021/dsa-4978
Third Party Advisory
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4
Vendor Advisory
Release Notes
https://access.redhat.com/security/cve/cve-2021-38160
Third Party Advisory
https://github.com/torvalds/linux/commit/d00d8da5869a2608e97cfede094dfc5e11462a46
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210902-0010/
Third Party Advisory